logo

Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers

ID: 918e97b6-427a-5486-9ff5-b9996357a1a9

STIX ID: report--918e97b6-427a-5486-9ff5-b9996357a1a9

Feed Name: HackRead

Threat Score
60/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Deeba Ahmed

...
...

Darktrace observed a campaign (18 March 2026) using a misconfigured Jenkins scriptText endpoint to gain RCE and distribute a cross-platform DDoS botnet that targets Valve Source Engine game servers; the report documents delivery artifacts (w.exe, bot_x64.exe), a single C2 IP (103.177.110.202), persistence techniques (env var dontKillMe, renaming to system-like processes), and attack modes that overload game server responses and specific ports (27015, 53, 123).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.